Courseiva
System Hardening →hardMultiple Select

CKS System Hardening Practice Question

A security engineer is hardening a cluster and wants to reduce the attack surface of Pods by restricting their access to host resources. The engineer is reviewing a Pod specification and plans to remove or disable settings that grant host-level access. Which two settings should the engineer remove or set to false to reduce the attack surface? (Choose two.)

⚠ Common exam trap

The trap here is focusing on privilege escalation or filesystem writability instead of the host namespace flags that actually grant host resource access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

hostPID: true

The hostNetwork and hostPID fields, when set to true, place the Pod in the host's network and PID namespaces respectively, giving it direct access to host resources and significantly increasing the attack surface. Removing or setting these to false isolates the Pod. The other options either represent secure settings that are already in place or address different security concerns not directly related to host resource access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    allowPrivilegeEscalation: true

    Why it's wrong here

    allowPrivilegeEscalation: true is an insecure setting, but it does not directly grant host-level access like host namespaces do. It allows a process to gain more privileges, which is a risk, but the question specifically targets host resource access. The correct settings to remove are the host namespace flags, not this one.

  • ✗

    readOnlyRootFilesystem: false

    Why it's wrong here

    readOnlyRootFilesystem: false means the container's root filesystem is writable, which is less secure than true, but it does not grant access to host resources. The question focuses on host-level access settings. A writable root filesystem is a separate concern from host namespace sharing, so this is not one of the two settings to remove.

  • ✓

    hostPID: true

    Why this is correct

    Setting hostPID to true places the Pod in the host's PID namespace, allowing it to see and potentially signal all processes on the node. Removing this setting or setting it to false isolates the Pod's process namespace, preventing it from viewing or interacting with host processes. This significantly reduces the attack surface.

  • ✓

    hostNetwork: true

    Why this is correct

    Setting hostNetwork to true places the Pod in the host's network namespace, giving it direct access to the host's network interfaces and allowing it to see all network traffic on the node. Removing this setting or setting it to false isolates the Pod's network stack, reducing the attack surface by preventing it from sniffing or interfering with host network traffic.

  • ✗

    privileged: false

    Why it's wrong here

    privileged: false is already the secure setting; it does not grant host-level access. The question asks for settings that grant host access and should be removed or set to false. Since privileged is already false, it does not need to be changed to reduce the attack surface. Setting it to true would increase risk, but that is not the scenario.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.